Account security
Argon2id password hashes, secure sessions, TOTP two-factor authentication, recovery codes, login throttling and sensitive-action reauthentication.
IMPLEMENTED CONTROLS
Account access, sensitive documents and financial records are protected through layered controls designed to reduce unauthorized access, detect manipulation and support recoverability.
Argon2id password hashes, secure sessions, TOTP two-factor authentication, recovery codes, login throttling and sensitive-action reauthentication.
Sensitive records and documents are encrypted using XChaCha20-Poly1305 when available, with authenticated AES-256-GCM fallback.
Atomic writes, file locks, transaction journals, append-only financial events and hash-chained audit ledgers make unauthorized changes detectable.
Role-based permissions separate compliance, portfolio management, finance, support, trading and audit responsibilities.
Encrypted backups include integrity manifests, safe restore workflow, pre-restore backup and post-restore verification.
CSRF protection, output escaping, path validation, Content Security Policy, HSTS, secure cookies and restrictive browser permissions.
Hosting configuration, secret management, access reviews, legal controls, account permissions and tested restore procedures must remain operational after deployment.